CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Vulnerabilities & CVEs
Intel Feed

cyberintel.kalymoon.com  ·  8250 articles  ·  updated every 4 hours · grows forever

8250Total
4161Full Text
Jun 10, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2019-25701 | Divxtodvd Easy Video to iPod Converter 1.6.20 user registration out-of-bounds write (Exploit 46255 / EDB-46255)

A vulnerability marked as critical has been reported in Divxtodvd Easy Video to iPod Converter 1.6.20 . This impacts an unknown function. This manipulation of the argument user registration causes out…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2019-25705 | Echo Mirage 3.1 Rules action out-of-bounds write (Exploit 46216 / EDB-46216)

A vulnerability described as critical has been identified in Echo Mirage 3.1 . Affected is an unknown function. Such manipulation of the argument Rules action leads to out-of-bounds write. This vulner…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
Adobe Reader Releases Emergency Patch For Zero-Day Vulnerability CVE-2026-34621 - LinkedIn

Adobe Reader Releases Emergency Patch For Zero-Day Vulnerability CVE-2026-34621 LinkedIn

LinkedIn Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6141 | danielmiessler Personal_AI_Infrastructure up to 2.3.0 parse_url.ts os command injection (ID 659)

A vulnerability was found in danielmiessler Personal_AI_Infrastructure up to 2.3.0 and classified as critical . Affected is an unknown function of the file Skills/Parser/Tools/parse_url.ts . Executing…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6142 | tushar-2223 Hotel Management System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15 /admin/roomdelete.php ID sql injection (Issue 15)

A vulnerability was found in tushar-2223 Hotel Management System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15 . It has been classified as critical . Affected by this vulnerability is an unknown func…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6143 | farion1231 cc-switch up to 3.12.3 ProxyServer server.rs cross-domain policy (Issue 1841)

A vulnerability was found in farion1231 cc-switch up to 3.12.3 . It has been declared as problematic . Affected by this issue is some unknown functionality of the file src-tauri/src/proxy/server.rs of…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-1116 | parisneo lollms up to 2.1.x AppLollmsMessage from_dict content cross site scripting

A vulnerability was found in parisneo lollms up to 2.1.x and classified as problematic . The impacted element is the function from_dict of the component AppLollmsMessage . Such manipulation of the arg…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6129 | zhayujie chatgpt-on-wechat CowAgent up to 2.0.4 Agent Mode Service missing authentication (Issue 2741)

A vulnerability was found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4 . It has been classified as critical . This affects an unknown function of the component Agent Mode Service . Performing a …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6130 | chatboxai chatbox up to 1.20.0 Model Context Protocol Server Management System ipc-stdio-transport.ts StdioClientTransport args/env os command injection (Issue 3627)

A vulnerability was found in chatboxai chatbox up to 1.20.0 . It has been declared as critical . This impacts the function StdioClientTransport of the file src/main/mcp/ipc-stdio-transport.ts of the c…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-31413 | Linux Kernel up to 6.12.79/6.18.20/6.19.10/7.0-rc1/7.0-rc4 bpf maybe_fork_scalars runtime out-of-bounds

A vulnerability was found in Linux Kernel up to 6.12.79/6.18.20/6.19.10/7.0-rc1/7.0-rc4 . It has been rated as critical . Affected is the function maybe_fork_scalars of the component bpf . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6131 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi setTracerouteCfg command os command injection

A vulnerability categorized as critical has been discovered in Totolink A7100RU 7.4cu.2313_b20191024 . Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6132 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi setLedCfg enable os command injection

A vulnerability identified as critical has been detected in Totolink A7100RU 7.4cu.2313_b20191024 . Affected by this issue is the function setLedCfg of the file /cgi-bin/cstecgi.cgi of the component C…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6133 | Tenda F451 1.0.0.7_cn_svn7958 /goform/SafeUrlFilter fromSafeUrlFilter page stack-based overflow

A vulnerability labeled as critical has been found in Tenda F451 1.0.0.7_cn_svn7958 . This affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter . Such manipulation of the argument …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6134 | Tenda F451 1.0.0.7_cn_svn7958 /goform/qossetting fromqossetting qos stack-based overflow

A vulnerability marked as critical has been reported in Tenda F451 1.0.0.7_cn_svn7958 . This vulnerability affects the function fromqossetting of the file /goform/qossetting . Performing a manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6135 | Tenda F451 1.0.0.7_cn_svn7958 /goform/SetIpBind fromSetIpBind page stack-based overflow

A vulnerability described as critical has been identified in Tenda F451 1.0.0.7_cn_svn7958 . This issue affects the function fromSetIpBind of the file /goform/SetIpBind . Executing a manipulation of t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6136 | Tenda F451 1.0.0.7_cn_svn7958 /goform/L7Im frmL7ImForm page stack-based overflow

A vulnerability classified as critical has been found in Tenda F451 1.0.0.7_cn_svn7958 . Impacted is the function frmL7ImForm of the file /goform/L7Im . The manipulation of the argument page leads to …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6137 | Tenda F451 1.0.0.7_cn_svn7958 /goform/AdvSetWan fromAdvSetWan wanmode/PPPOEPassword stack-based overflow

A vulnerability classified as critical was found in Tenda F451 1.0.0.7_cn_svn7958 . The affected element is the function fromAdvSetWan of the file /goform/AdvSetWan . The manipulation of the argument …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6138 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi setAccessDeviceCfg mac os command injection

A vulnerability, which was classified as critical , has been found in Totolink A7100RU 7.4cu.2313_b20191024 . The impacted element is the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi o…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6139 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi UploadOpenVpnCert FileName os command injection

A vulnerability, which was classified as critical , was found in Totolink A7100RU 7.4cu.2313_b20191024 . This affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component C…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6140 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi UploadFirmwareFile FileName os command injection

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024 and classified as critical . This impacts the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of the component CGI …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
Critical Ivanti EPMM Zero-Day Vulnerabilities Exploited in the Wild, Targeting Corporate Networks - gbhackers.com

Critical Ivanti EPMM Zero-Day Vulnerabilities Exploited in the Wild, Targeting Corporate Networks gbhackers.com

gbhackers.com Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-31845 | Rukovoditel CRM up to 3.6/3.6.4 API Endpoint /api/tel/zadarma.php zd_echo cross site scripting (EUVD-2026-21682)

A vulnerability, which was classified as problematic , has been found in Rukovoditel CRM up to 3.6/3.6.4 . This issue affects some unknown processing of the file /api/tel/zadarma.php of the component …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6125 | Dromara warm-flow up to 1.8.4 Workflow Definition /warm-flow/save-json SpelHelper.parseExpression listenerPath/skipCondition/permissionFlag code injection (IHURVQ)

A vulnerability, which was classified as critical , was found in Dromara warm-flow up to 1.8.4 . Impacted is the function SpelHelper.parseExpression of the file /warm-flow/save-json of the component W…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 12, 2026
CVE-2026-6126 | zhayujie chatgpt-on-wechat CowAgent 2.0.4 Administrative HTTP Endpoint missing authentication (Issue 2733)

A vulnerability has been found in zhayujie chatgpt-on-wechat CowAgent 2.0.4 and classified as critical . The affected element is an unknown function of the component Administrative HTTP Endpoint . Thi…

VulDB Read →
← Prev 209 / 344 Next →